The Intel Bug Bounty Program has been suspended, with rewards that once reached $100,000 for a single flaw, replaced on the Intigriti platform by a disclosure scheme that pays nothing. Intigriti’s page for the new arrangement states plainly that it “is a responsible disclosure program without bounties.” Intel has given no reason for the change, and the old bounty board is still visible on the site, now marked as suspended rather than removed.
How the Intel bug bounty program was structured
The program began invite-only in 2017 and opened to all outside researchers a year later, eventually covering Intel’s software, hardware, firmware and open-source projects. Its own page, still live, describes awards ranging from $500 up to $100,000 depending on the quality of a report and other factors, split across four tiers. Intel had also been expanding the scheme rather than winding it down: coverage for its web services was added sometime between the middle of 2025 and October 2025, only months before the reversal.
Public accounts of exactly how those tiers broke down do not agree with each other. Tom’s Hardware lists Tier 1 at $2,000 to $100,000, Tier 2 at $1,000 to $30,000, Tier 3 at $500 to $10,000 and Tier 4 at $250 to $5,000. TechPowerUp instead puts the top payout in Tier 4, with $5,000 for Tier 1, $10,000 for Tier 2, $30,000 for Tier 3 and $100,000 reserved for Tier 4-level disclosures such as Spectre or Meltdown. By our reading, neither breakdown matches which tier Intel’s own page still credits with the $100,000 ceiling, so any secondhand account of the old pricing should be treated as approximate rather than official.
AI and the shrinking incentive for bug hunters
Both outlets that reported the suspension point toward the same likely driver: AI-assisted bug hunting has made the pay-per-report model harder to sustain. TechPowerUp suggested Intel’s own tools, likely AI-assisted, can now find and patch many flaws internally before an outside researcher gets there first. Tom’s Hardware noted that open-source projects, including the Linux kernel, have been swamped with automatically generated vulnerability reports, and that kernel CVEs have climbed toward 2,000 per release cycle. Whatever the cause, the shift arrived fast: Tom’s Hardware reports that Intel posted a January 6 update on Intigriti saying it was evaluating “enhanced bounty and bonus criteria,” and roughly eight months later the whole program was suspended rather than expanded.
This isn’t the first time AI’s growing role in security research has shown up on this site. In our earlier piece on how Hacktron used Claude to hack OpenAI’s ChatGPT accounts, the concern was AI turned toward offense, breaking into other people’s accounts. Intel’s move points the same trend the other way: fewer outside researchers financially incentivised to hunt for flaws, and more reliance on automated systems checking Intel’s own code before anyone outside the company does.
Worth watching now is whether Intel reintroduces paid tiers once it finishes whatever internal review led to the suspension, and whether the CVE counts in its next few patch cycles shift once the financial incentive for outside researchers has gone.
Image: Intel in Deutschland via Wikimedia Commons, licensed under CC BY-SA 2.0.








